Technology · Go
github.com/pomerium/pomerium (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in github.com/pomerium/pomerium (Go): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-50285, was published on 17 September 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About github.com/pomerium/pomerium (Go)
An identity-aware proxy that provides secure access to internal applications and infrastructure.
Latest github.com/pomerium/pomerium (Go) vulnerabilities
- CVE-2026-50285: Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs…highCVSS 7.5EPSS 0.7%
- CVE-2024-47616: GO-2024-3179 - Pomerium service account access token may grant unintended access to databroker API in…lowCVSS 3.1EPSS 0.6%
- CVE-2021-39162: GO-2022-0933 - Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 1.6%
- CVE-2021-29652: GO-2022-0827 - pomerium_signature is not verified in middleware in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.7%
- CVE-2021-29651: GO-2022-0783 - JWT leak via Open Redirect in Programmatic access in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.7%
- CVE-2022-24797: GO-2022-0413 - Exposure of Sensitive Information in Pomerium in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 1.4%
- CVE-2023-33189: GO-2023-1800 - Pomerium vulnerable to Incorrect Authorization with specially crafted requests in…lowCVSS 3.1EPSS 0.9%
- CVE-2024-39315: GO-2024-2965 - Pomerium exposed OAuth2 access and ID tokens in user info endpoint response in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.4%
- Multiple security issues in Pomerium's embedded envoyinfo
- CVE-2021-41230: GO-2021-0258 - Incorrect authorization in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.9%
Most severe github.com/pomerium/pomerium (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-50285: Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs…highCVSS 7.5EPSS 0.7%
- CVE-2021-39162: GO-2022-0933 - Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 1.6%
- CVE-2022-24797: GO-2022-0413 - Exposure of Sensitive Information in Pomerium in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 1.4%
- CVE-2023-33189: GO-2023-1800 - Pomerium vulnerable to Incorrect Authorization with specially crafted requests in…lowCVSS 3.1EPSS 0.9%
- CVE-2021-41230: GO-2021-0258 - Incorrect authorization in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.9%
- CVE-2021-29652: GO-2022-0827 - pomerium_signature is not verified in middleware in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.7%
- CVE-2021-29651: GO-2022-0783 - JWT leak via Open Redirect in Programmatic access in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.7%
- CVE-2024-47616: GO-2024-3179 - Pomerium service account access token may grant unintended access to databroker API in…lowCVSS 3.1EPSS 0.6%
- CVE-2024-39315: GO-2024-2965 - Pomerium exposed OAuth2 access and ID tokens in user info endpoint response in github.com/pomerium/pomeriumlowCVSS 3.1EPSS 0.4%
- Multiple security issues in Pomerium's embedded envoyinfo
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-pomerium-pomerium.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/pomerium/pomerium (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-pomerium-pomerium, 28 September 2026.